CVE-2023-6553
Backup Migration unauthenticated remote code execution through attacker-controlled includes in backup-heart.php
- Severity
- critical
- Affected product
- backup-backup
- Affected versions
- backup-backup ≤ 1.3.7
- Fixed in
- backup-backup 1.3.8
- Added to NewScan
- 2026-09-09
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints backup-backup from its response and reports this CVE when the detected version falls inside the affected range below.
The WordPress plugin slug is backup-backup. CVE-2023-6553 affects every release through 1.3.7 and is fixed in 1.3.8; unauthenticated callers control paths consumed by includes/backup-heart.php and can reach PHP execution. scan_wordpress probes this readme only after WordPress is confirmed, and records the advisory only when its Stable tag is inside the affected range. Version-match only: actively proving the issue would execute PHP on the customer's server.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →